ARTEMIS: Adaptive Reweighing for Transferable Evasion via Meta-learning in Zero-Query Network Intrusion Detection Systems
Lei Wang, Qingsong Zou, Qing Li, Jianping Zhang, Yong Hua Jiang · 2025
Machine Learning-based Network Intrusion Detection Systems (ML-NIDSes) are vital for cyber-security, yet their inherent vulnerability to adversarial attacks poses a persistent challenge. Among these, zero-query transfer-based attacks present a particularly realistic and formidable threat, as adversaries operate with no knowledge of or interaction with the target NIDS. However, the efficacy of such attacks is critically hampered by poor adversarial transferability across diverse NIDS model architectures and by strict protocol-defined constraints on network traffic modifications. To probe the robustness of NIDSes under zero-query attacks, we introduce ARTEMIS, a novel hybrid attack framework engineered to dramatically enhance adversarial transferability for zero-query attacks. ARTEMIS leverages the generalization capabilities of meta-learning to adapt to unknown target models by simulating diverse black-box transfer tasks. Simultaneously, it combines a reinforcement learning-inspired adaptive reweighing mechanism to maximize transfer potential by promoting the effective use of heterogeneous substitute ensembles. Extensive evaluations on the BCCC-CIC-IDS2017/2018 datasets across closed-set, open-set, and cross-set zero-query scenarios confirm that ARTEMIS significantly outperforms state-of-the-art baselines. Our work presents a powerful methodology for NIDS vulnerability assessment and provides crucial insights for developing defenses against transfer-based evasions.